Checking job availability...
Original
Simplified
Overview:
The role of the Head of Info Sec is a second line risk management role and function to define and mature information security practices and standards across ALI, including affiliates and subsidiaries. Working closely with the Technology Information Security Officer (TISO), the Head of Info Sec provides oversight over line functions including the technology Trust and Security function, for compliance and adherence to information security policies and standards as defined in the protective security framework.
Responsibilities include but not limited to the ff:
- Second line risk management role and function that is specific to Information Security across the enterprise
- Owns the policies and standards that define the overall protective security framework for Enterprise data that are collected, stored, and processed by the ALI group, its affiliates and subsidiaries
- Ensures that the policies and standards conform to the requirements of the National Privacy Commission (NPC) of the Philippines and other applicable Data Privacy regulations and security standards, both local and international
- Equally accountable with the business for implementing controls that conform to Enterprise standards to address business risks related to information security, including a response plan, and the definition and implementation of mitigation and contingency plans for all information security risks
- Works with Enterprise Technology and the Technology Information Security Officer on various information security risks, including current and emerging risks, on its assessment and implementation of required controls.
Qualifications: Technical Knowledge, Competencies, and Experience
- 18+ years work experience in Information security and with broad experience in Risk Management
- Preferably with a Bachelor's degree in Computer Science, Information Technology, Engineering, or related field
- Excellent knowledge of information security and data privacy regulations both in the local and international space, information security standards and policies from a risk management standpoint with a good appreciation of technology related to information security
- Excellent process orientation, problem-solving and analytical skills, and exceptional attention to details
- Well-rounded risk management practitioner with practical project management experience in the roll-out of policies and standards across an Enterprise
- Good organization skills with business acumen, to be able to influence change across an enterprise. Strong foundational knowledge and experience on the three (3) lines of defense from an organizational standpoint